Gentoo Archives: gentoo-hardened

From: Peter Hjalmarsson <xake@×××××××××.net>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Re: foldingathome and PAX
Date: Mon, 20 Apr 2009 19:53:43
Message-Id: 1240257188.12686.11.camel@lillen.dodi
In Reply to: Re: [gentoo-hardened] foldingathome and PAX by pageexec@freemail.hu
1 mån 2009-04-20 klockan 21:13 +0200 skrev
2 pageexec@××××××××.hu:
3 > On 20 Apr 2009 at 21:03, Peter Hjalmarsson wrote:
4 >
5 > > I realised earlier today that foldingathome (installed with the help of
6 > > portage) had not started a new WU since 5 of april, and when I started
7 > > to investigate I found out that the "cores" had problem running.
8 > >
9 > > cd /opt/foldingathome &&
10 > > paxctl -c FahCore_*.exe &&
11 > > paxctl -PEMrXS FahCore_*.exe
12 > >
13 > > makes it work again.
14 > > foldingathome has worked in the past without problems, and I do not
15 > > really know what have changed more then some kernel-upgrades (but
16 > > booting the last kept 2.6.27-hardened did not help either) and keeping
17 > > the userland up to stable x86.
18 > > What can I do to not have to do this dance?
19 >
20 > can you re-enable pax on the binaries and see if they produce any logs
21 > (pax kills)? if they do, try to remove mprotect only and see if that
22 > helps. the other issue could be a bad glibc and lack of GNU_STACK headers,
23 > execstack -c would fix that without having to compromise on pax.
24 >
25 >
26 >
27
28 I find nothing in ay logs from pax what ever I try, the reason I tried
29 with PAX-permissions was a hounch.
30 Only disable mprotect does not change anything.
31 I cannot find execstack on the system, what package provides that file?

Replies

Subject Author
Re: [gentoo-hardened] Re: foldingathome and PAX pageexec@××××××××.hu